Uptime Hamster: 11d 13h 47mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza crylock

crylock

2 incidentes 2 paises 0 sectores ransomware RU Ultimo: 2026-06-29
Aliases: Cryakl
Ver en IntelTracker → APTTrail →
CryLock is a ransomware operation that emerged in April 2020 as a variant of the Cryakl ransomware family, also known as Fantomas. This group is primarily motivated by financial gain through cryptoviral extortion, demanding cryptocurrency payments for file decryption. A distinguishing feature of CryLock is its file renaming convention during encryption, where it appends a developer's email, a unique victim ID, and a randomized three-letter extension to affected files. The group has shown an evolution in its operational model, moving towards a semi-affiliate structure offering customizable options to partners. While primarily employing encryption, some instances suggest the group may also operate as a data broker, or adopt a double extortion model by exfiltrating sensitive data and threatening its public release.

Aliases del actor

Cryakl

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / onionunknownd57uremugxjrafyg.onioncrylock
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: crylock
Tecnicas MITRE
T1078, T1486, T1566.001, T1027, T1047
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1) Russia (1)

Paises objetivo (SOCRadar)

BelgiumBrazilGermanySpainUnited KingdomItalyPortugalUnited States

Sectores objetivo (SOCRadar)

Energy & Utilities ManufacturingInformation ServicesFinanceProfessional&Technical ServicesEnterprises & HoldingEducational ServicesHealthCare & Social AssistanceOtherPublic Administration

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com